pica-vercel-ai-sdk

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The guide correctly explains how to wire PICA's MCP into the Vercel AI SDK, but includes risky operational recommendations: (1) using npx to run @picahq/mcp without advising pinned versions or integrity checks (download-and-execute risk), and (2) spreading the entire process.env into the subprocess, which exposes unrelated secrets to a third-party process. These practices increase supply-chain and credential-exfiltration risk. Remediation: pin or install the MCP package, forward only needed env vars (PICA_SECRET and PATH), run the subprocess with reduced privileges or sandboxing, and monitor/audit subprocess network activity.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 11:34 AM
Package URL
pkg:socket/skills-sh/picahq%2Fskills%2Fpica-vercel-ai-sdk%2F@33a32d719a15ca7048baac2694489f954b63a02e